Senior [Red Team] Security Consultant
Banglore
Posted Date :2024-03-01
Applicants for this position should demonstrate leadership and sound business judgment in anticipating client/project needs and developing alternative solutions.
Responsibilities:
- Compromising the target’s security by extracting information, infiltrating its systems, or breaching its physical perimeters.
- Evading detection by the blue team, often operating within narrow timeframes that challenge the blue team's ability to neutralize threats before damage occurs.
- Exploiting bugs and weaknesses in the target’s infrastructure to identify gaps in technical security and enhance overall security posture.
- Initiating hostile activities, including sophisticated penetration testing, to assess the blue team’s defensive capabilities reliably.
Skill Sets:
- Conducting initial reconnaissance using open-source intelligence (OSINT) to gather information on the target.
- Deploying command-and-control servers (C&C or C2) to establish communication with the target’s network.
- Utilizing decoys to mislead the blue team.
- Applying social engineering and phishing techniques to manipulate employees into compromising their machines or revealing sensitive information.
- Performing physical and digital penetration testing.
- Conducting network penetration testing and manipulating network infrastructure.
- Scripting or automating tasks using Perl, Python, or Ruby.
- Developing, extending, or modifying exploits, shellcode, or exploit tools.
- Reverse engineering malware, data obfuscators, or ciphers.
- Demonstrating a thorough understanding of network protocols, data on the wire, and covert channels.
- Mastery of Unix/Linux/Mac/Windows operating systems, including bash and PowerShell.
- Building security tools and automating Red Teaming workflows.
- Utilizing Threat Modeling methodologies to identify threats and shape Red Team operations.
- Understanding Mitre’s ATT&CK Framework.
- Possessing certifications from SANS and Offensive Security is highly desirable.
- Conducting Web Penetration Testing (OWASP and SANS).
Key Responsibilities for Cyber Security Consultants:
- Proficiency with leading commercial and open-source automated reconnaissance and penetration testing tools and services.
- Ability to perform targeted penetration tests without relying solely on automated tools.
- Familiarity with networking fundamentals.
- Understanding of application design principles.
- Knowledge of web and mobile application exploitation methodologies.
- Ability to independently research new vulnerabilities in software products.
- Familiarity with the fundamentals of software exploitation on modern operating systems.
Qualifications:
- Minimum 2 years of experience performing network, web, and mobile application penetration tests.
- Offensive Security Certified Professional (OSCP) / Offensive Security Certified Expert (OSCE).
- Certified Ethical Hacker (CEH).